Attackers behind the $387.5 million Bitget hack did not steal the exchange’s private keys. They fed forged instructions into Bitget’s own transaction-signing system, which then approved the transfers as if they were legitimate, according to an independent analysis published on September 26 by blockchain security firm GoPlus Security.
The GoPlus review is based on Bitget’s public statements and on-chain timing data, not on an official Bitget postmortem. It places the September 24 incident in the same failure class as the February 2025 Bybit theft. Bitget, one of the largest centralized cryptocurrency exchanges by trading volume, is scheduled to begin restoring withdrawals in phases from today, September 28.
What GoPlus Found
“This was not a private-key leak. It was another break in the transaction-signing trust chain,” GoPlus wrote in its September 26 analysis.
A private key is the secret credential that authorizes the movement of funds from a crypto wallet. GoPlus says the attackers never needed it. Instead, they caused Bitget’s own signing system to produce valid signatures for transfers the exchange never intended to send, and those transfers then confirmed on-chain.
The compromise was limited to some of Bitget Exchange’s hot wallets, which stay connected to the internet to process routine withdrawals, and warm wallets, which sit between hot and offline storage. GoPlus says cold storage, the offline reserve, was not affected. Neither was Bitget Wallet, a separately operated self-custody product.
Bitget first put the loss at $351.6 million before revising the figure to $387.5 million. The $35.9 million difference came from Zcash (ZEC) and TRON (TRX) transfers made during the original attack window, not from a second breach. The Crypto Times reported both the initial loss and the revised count on September 25.
The GoPlus reading matches the first-day account from Bitget Chief Executive Officer (CEO) Gracy Chen. In a September 24 security notice, Chen said a critical wallet backend system was compromised, transaction data was spoofed, and the authorization process was triggered. She said the attackers did not forge user withdrawal requests and did not obtain private keys for cold, hot, or warm wallets.
GoPlus frames that as the difference between stealing a key and poisoning the instruction that tells the signer what to approve.
Timeline of the Drain
GoPlus reconstructed the attack as follows. All times are in Coordinated Universal Time (UTC) on September 24.
- 18:31: An attacker-controlled address was funded with 0.84 ETH to pay network fees, known as gas. The ETH came from a Bitget hot wallet already under the attacker’s control. Bitget says it detected unauthorized transfers in the same minute.
- 18:58: The first large outflow, about $34.75 million in Tether (USDT), went to the same address funded 27 minutes earlier.
- 19:00 onward: Stablecoins were swapped for Ether (ETH) on decentralized exchanges (DEXs) and bridged to Ethereum.
- 19:16: The largest wave moved about $185 million in roughly one minute, including 13,966 ETH on Ethereum, about 91.4 million XRP on the XRP Ledger, and 20.6 million TRX on TRON.
- 18:58 to 21:23: A multi-chain drain lasting 2 hours and 25 minutes covered ETH, USDT, USD Coin (USDC), Avalanche (AVAX), BNB, Tether Gold (XAUt), XRP, and TRX.
- About 21:30: Chen posted the security notice, and Bitget paused withdrawals.
- About 22:00: Roughly $155 million on chains compatible with the Ethereum Virtual Machine (EVM) was split across multiple dormant vault addresses.
XRP made up the largest slice of the stolen assets, a point The Crypto Times covered separately.
GoPlus describes the 0.84 ETH transfer as a dry run. It showed that the attackers could already drive Bitget’s signing path nearly half an hour before the main drain began.
The firm argues the timing matters more than the headline figure. Detection and the first gas funding happened in the same minute, yet the last unauthorized transfer went out at 21:23, almost three hours later. GoPlus says the transfers likely looked legitimate to internal monitoring, or the signing pipeline had no kill switch that could be triggered remotely.
If a circuit breaker had stopped the pipeline after the first $34.75 million USDT transfer, GoPlus estimates that about 90% of the funds would have stayed with the exchange.
Why the Signer Could Not Stop It
GoPlus maps a standard withdrawal path at a centralized exchange in four steps: a user request, backend risk checks, construction of an unsigned transaction, and finally signing and broadcast.
The signing step typically relies on one of three tools. Multi-party computation (MPC) splits control of a key across several parties so no single one holds it in full. A multi-signature (multisig) wallet requires several separate approvals. A hardware security module (HSM) is a tamper-resistant device that stores keys and signs transactions.
According to GoPlus, none of these can judge intent. They sign what the backend hands them. Once attackers poisoned the data that defines what to sign, controls on that same backend, including rules, limits, and approvals, could not veto the action independently. In the firm’s words, the attackers took the risk-decision layer, not the key layer.
GoPlus lists possible entry points only as speculation: database tampering, forged internal calls, message-queue injection, or a swap of the withdrawal-address map. None has been confirmed. Bitget has said it identified and fixed the weakness, but it has not published the entry point. Mandiant, a Google company, and blockchain security firm SlowMist are still investigating.
Same Failure Class as Bybit, Different Surface
GoPlus draws a structural comparison with the February 2025 Bybit theft, which the United States Federal Bureau of Investigation (FBI) put at about $1.5 billion. In that case, attackers tampered with the interface of Safe, a multisig wallet provider, so Bybit’s human signers saw one transaction and approved another.
At Bitget, GoPlus says, there was no human review step to deceive. Automated signing ran on forged backend data.
The firm ties both incidents to the same principle, known as WYSIWYS, or “what you see is what you sign.” Bybit broke on the front end. Bitget broke on the back end.
Both cases are also being linked to hacking clusters associated with the Democratic People’s Republic of Korea (DPRK), commonly known as North Korea. The FBI formally attributed the Bybit theft to North Korea. The Bitget attribution is not settled. Chen has said investigators matched some IP activity to a VPN pattern used by a known DPRK group and that the on-chain pattern resembles earlier operations, describing North Korean involvement as “very likely.” The Crypto Times covered those remarks when she first made them. Bitget has not released the technical evidence behind the assessment.
Attacker Addresses and Tracing
GoPlus says it has blacklisted attacker-linked addresses and shared them with ecosystem partners. First-hop receiving addresses published early in the incident include:
- 0xA6dD3F218B65E32Ccc37BE30f74884133c655545
- 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899
- 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2
- 0x94A43df7687A8494948Be937400e9d5D33135DA0
- 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
- 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C
The number of related addresses has since grown to nearly 900 as the funds were split and moved. Bitget’s stolen-funds tracker remains the exchange’s public map of attacker holdings and transfers. Chen said earlier that some hacker wallets had been frozen.
What It Means for Bitget Users
The GoPlus review does not change the operational picture for customers. Bitget says user balances were not altered, and neither cold storage nor Bitget Wallet has been reported as affected. The exchange says the shortfall is covered by its User Protection Fund, a reserve Bitget maintains to compensate users for losses from security incidents.
Under the plan Bitget posted on September 26, withdrawals return in phases starting September 28, beginning with bitcoin (BTC). The Crypto Times has published the full withdrawal schedule, details of Bitget’s 5% recovery bounty, and an analysis of how the incident compares with FTX.
What the Review Does Not Settle
GoPlus is an independent security firm, not Bitget’s incident responder. Its analysis isolates a control failure that Bitget’s early notices described only in outline, but it is not a root-cause report. It does not identify the attackers’ first foothold, and it does not resolve the question of North Korean involvement.
Two questions remain open. The first is how the attackers entered Bitget’s wallet backend. The second is why a detection logged at 18:31 UTC did not stop transfers that continued until 21:23 UTC. As GoPlus frames it, a signing system that cannot independently flag a first-seen receiving address, a burst across multiple wallets, or a $185 million one-minute outflow is a single point of failure, even when every private key stays secure.
This is a developing story. The Crypto Times will update this report when Bitget publishes a full technical incident report or when independent tracing changes the timeline or the signing-path conclusion.
Also Read: Vietnamese Man Charged Over $16M Crypto Pig Butchering Scam
